Security Incidents mailing list archives

Re: Re : Large scale scan of port 2401


From: axess <axess () alldas de>
Date: Thu, 23 Aug 2001 20:31:40 +0200 (CEST)

On Thu, 23 Aug 2001, John Marquart wrote:


Sorry if my mail was was abit confusing.

Last Stage of Delirium Research Group is a non-profit informal organization
that released some remote and local (POC) proof of concept exploits codes
for AIX some time ago.

These are now widely used to penetrate AIX systems by defacers and
other individuals that want access to systems around the internet.

Mr Olsson,
      Could you elaborate on your comments below - i.e. what AIX uses
the port for, what the LSDRG is/does what POC is?   Presumably an exploit
of some sort?

thanks,
-john


On Thu, 23 Aug 2001, axess wrote:


2401/tcp  cvspserver

This port is used by AIX and with the recent contribution from
Last Stage of Delirium Research Group with many POC codes to the world.
Im sure those scans was aimed to locate servers running AIX in a
fast and easy way.

--
Mikael Olsson
axess - axess () alldas de
system administrator

IT-Security Information Network
http://www.alldas.de


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com




John "Jamie" Marquart         |     This message posted 100% MS free.
Digital Library SysAdmin      |  Work: 812-856-5174   Pager: 812-334-6018
Indiana University Libraries  |  ICQ: 1131494         D'net Team:  6265


-- 
Mikael Olsson
axess - axess () alldas de
system administrator

IT-Security Information Network
http://www.alldas.de


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: